The UAE Cyber Security Council, the United Arab Emirates' national cyber authority, said on 10 August that national Teams had detected and contained coordinated attacks on aviation, energy and education before the attackers reached their objectives or affected service continuity 1. Its description covers attempted breaches of digital infrastructure, attempts on operational accounts and data, targeted phishing, and attempts to use staff as a way in.
The statement omits everything a reader could check. No actor is named, no victim organisation, no product, no technique beyond the categories above and no date for the attacks themselves. Nobody outside the Council can verify any of it, and nobody outside the affected organisations can act on it, because there is no indicator to search a network for.
The Council has now made two such announcements in two months, after the financial-sector intrusion attempts it reported detecting on 3 July. Two in two months reads as a communications policy rather than coincidence, and the policy has a rationale: a national authority that only appears in public after a successful attack teaches its own economy that it exists to announce failures.
Institutions elsewhere have taken the opposite decision with a similar amount of substance. The G7 Cyber Expert Group closed its 2026 cross-border coordination exercise on or before 31 July without publishing a scenario, a participant list or findings . One body says little and names it an announcement; the other says nothing at all. Neither leaves an operator in the covered sectors anything to do differently on Monday.
